
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2013-10065 is a denial-of-service (DoS) vulnerability in Sysax Multi-Server version 6.10 affecting its SSH daemon. A specially crafted SSH key exchange packet containing a non-standard byte (\x28) in place of the expected SSH protocol delimiter can trigger a crash in the SSH service, resulting in complete loss of availability. The vulnerability was originally discovered in 2013 but formally assigned a CVE and published in August 2025. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Red Hat CVE, VulnCheck Advisory).
The root cause is classified as CWE-248 (Uncaught Exception), where the SSH daemon in Sysax Multi-Server 6.10 fails to properly handle malformed key exchange data during the SSH handshake process. When a client sends a key exchange packet with a non-standard byte (0x28) substituted for the expected SSH protocol delimiter, the daemon does not catch the resulting exception and crashes. The attack requires no authentication, no user interaction, and is remotely exploitable over the network with low complexity. A public technical write-up and a Metasploit auxiliary module are available detailing the exploitation mechanics (Matt Andreko Blog, Metasploit Module).
Successful exploitation causes the SSH daemon in Sysax Multi-Server 6.10 to crash, resulting in a complete loss of SSH service availability. This disrupts remote access and management capabilities for the affected server. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Repeated exploitation could keep the SSH service persistently unavailable, effectively locking administrators out of remote management (Red Hat CVE, VulnCheck Advisory).
Public proof-of-concept exploit code is available in two forms: a researcher blog post from 2013 and a Metasploit auxiliary module (auxiliary/dos/windows/ssh/sysax_sshd_kexchange), making exploitation straightforward for any attacker with basic tooling (Metasploit Module, Matt Andreko Blog). No authentication is required, and the attack can be launched remotely with no user interaction. There is currently no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating low probability of near-term exploitation (Red Hat CVE).
auxiliary/dos/windows/ssh/sysax_sshd_kexchange in the Metasploit Framework.RHOSTS parameter to the target IP address and RPORT to the SSH service port.0x28 in place of the expected SSH protocol delimiter.No specific vendor patch information is publicly available for this vulnerability. The following mitigations are recommended: restrict SSH access to trusted IP ranges using firewall rules; implement network-level filtering to block or rate-limit inbound SSH connections from untrusted sources; deploy an intrusion detection/prevention system (IDS/IPS) capable of detecting malformed SSH key exchange packets; monitor SSH service logs for anomalous connection patterns; and consider migrating to a newer, actively maintained SSH server solution if an updated version of Sysax Multi-Server is not available (VulnCheck Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."